Privacy
Your draft starts on your device—and stays there until you decide otherwise.
SitSorted is designed around data minimisation. This page explains what stays in your browser, what is stored when you choose account features, and how to contact us about your information.
Public generators
Answers are saved in your browser’s local storage, separately for each tool, and expire after 30 days of inactivity. Creating, reloading, copying and printing a draft does not transmit generator field values to SitSorted.
If storage is unavailable, the tool still works for the current page session and tells you that autosave is unavailable.
Owner accounts and import
Invited owners sign in by email magic link. A local draft remains local after sign-in. Only an explicit final confirmation imports the reviewed content. Import receipts retain a fingerprint and operational metadata, never another copy of the raw draft.
Owner access requests
When you request owner access, the form sends the name and email address you provide through Resend to support@sitsorted.com. A person reviews each request and responds manually. Submitting the form does not create an account or guarantee access.
The request is not added to a marketing list or written to the SitSorted product database. If access is approved, the email address may later be added manually to the invite allowlist; subsequent authentication and account records are handled as described in this notice.
- Request emails are kept only while needed to review and respond to the request.
- We may keep limited correspondence for longer when necessary to record an access decision, prevent abuse, resolve a dispute or meet a legal obligation.
- Request details are deleted when they are no longer needed for those purposes.
- You can withdraw a pending request or ask about its retention by emailing support@sitsorted.com.
Live sitter briefs
A sitter link is a private bearer secret. The raw token is shown once, while only its cryptographic digest and last four characters are stored. On exchange, the browser receives a short-lived secure cookie and moves to a token-free URL. Every sitter request rechecks that the link is still valid.
What the product does not ask for
- Exact home addresses, access codes, alarm codes or Wi-Fi credentials.
- Payment details, microchip numbers, uploads or full medical records.
- In-app chat messages, advertising profiles or third-party tracking identifiers.
Limited product analytics
On allowlisted public pages, SitSorted records an anonymous page view and estimates a visit when someone enters from outside the site or opens the page directly. Moving between public pages adds page views but not another estimated visit. The browser reduces the entry source to a coarse category—direct or unknown, organic search, organic social, an approved campaign or another referral—before anything is sent.
These measurements use no analytics cookies or unique visitor identifiers. SitSorted rejects names, draft or issue text, contacts, tokens, raw referrers, search queries, full URLs, exact dates, IP addresses and user-agent strings. Private owner, sitter, API, token and unknown routes are excluded.
Activity associated with a signed-in pilot administrator is excluded from collection. Administrator email addresses are checked only against the server-side access list and are never written to analytics.
Founder reporting can request aggregate clicks, impressions, click-through rate, average position, dates and allowlisted page paths from Google Search Console. For the founder-only Growth Pilot, exact search queries are processed transiently in request memory and immediately reduced to an allowlisted, coarse sitter-preparation topic. Brand searches, unrelated or unclassified text and topics below the two-period privacy threshold are discarded. Exact queries are never logged, stored or returned, and countries and devices are never requested. Search Console responses are not persisted.
A founder can create a time-limited Growth Pilot agent token for an explicitly invoked Codex workflow. SitSorted stores only the token's cryptographic digest, last four characters, label, exact scopes, expiry, last-used and revocation timestamps. The token cannot access owner information, page content, Google credentials or deployment controls. Event-level SitSorted analytics are deleted after 90 days; aggregate experiment results may be retained for up to 18 months so the founder can compare which types of change have worked.
The founder-only Trend Radar can read official public UK trend feeds and, when separately configured, aggregate search or social trend services. Provider responses, social post or video titles, account names, channel identifiers and full URLs are filtered in request memory and never stored. A safe, normalised public trend label may be kept in a broad viral watchlist for up to 30 days even when it has no initial SitSorted relationship. Sensitive, commercial-local and unsafe topics are discarded. A founder-invoked Codex review must establish a real owner or sitter benefit before a trend can inform a page or guide. A label linked to an aggregate experiment may be retained with that experiment for up to 18 months. No content is written, posted or published automatically.
Browser storage and essential cookies
The free tools use local browser storage so a draft can survive a reload. Signed-in owner sessions and opened sitter briefs use secure, essential cookies for authentication and access control. SitSorted does not use advertising cookies or third-party behavioural tracking.
Outreach and partnerships
SitSorted may contact an incorporated organisation at a published editorial, partnerships or resource-submission address when a specific free guide or tool appears relevant to its audience. We use publicly available business-contact details for limited, individually researched business outreach under our legitimate interests in responsibly introducing SitSorted. We do not use bulk sequences, purchased lists or email tracking pixels.
We do not cold-email sole traders, personal addresses or organisations whose corporate status is uncertain without consent. Every message identifies SitSorted, links to this notice and provides a clear way to opt out.
- Records may include the organisation and domain, relevant resource page, public contact source, business email address, fit notes, contact dates, response, opt-out and any resulting placement.
- Ordinary prospect records are deleted 12 months after the last contact.
- When someone objects, we keep only the minimum address or domain and objection date needed to honour that suppression.
- To object, opt out or ask about these records, email support@sitsorted.com.
Your choices and contact
SitSorted is an independent online service based in England. For privacy questions or requests, email support@sitsorted.com. This address is not an emergency channel.
- Clear any local draft immediately from its tool.
- Archive completed trips and restore them later through account settings.
- Submit or cancel a verified account-deletion request through account settings.
- Revoke or replace a sitter link to end existing access.
Retention and your rights
Local drafts expire after 30 days of inactivity. Event-level analytics and directly matched daily trend signals are deleted after 90 days. Unlinked viral-watchlist labels and trend collection-health records are deleted after 30 days, and expired rate-limit buckets after 48 hours. Aggregate trend decisions and experiment results may be retained for up to 18 months. Account and trip information is retained while it is needed to provide the service or meet a valid legal obligation. Depending on your circumstances, you may ask for access, correction, deletion, restriction or a portable copy of personal information, or object to certain uses, including business outreach. You may also complain to the UK Information Commissioner’s Office.